DineCanvas
Privacy Policy
Last updated: [DATE] · Effective date: [DATE]
1. Introduction
This Privacy Policy explains how [LEGAL ENTITY NAME, e.g. "DineCanvas Technologies Private Limited"] ("DineCanvas", "we", "us", "our"), the operator of the DineCanvas Restaurant Operating System (the "Platform"), collects, uses, shares, and protects personal data, in accordance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and its rules.
This Policy applies across all DineCanvas surfaces: the marketing website, the owner/staff dashboard, the platform console, the QR/online ordering experience diners use at DineCanvas-powered restaurants, and the kitchen display system.
2. Who this Policy covers
DineCanvas is a platform that restaurants use to run their business. Because of that, this Policy covers three different groups of people, and what we collect differs for each:
- Restaurant owners and staff — the people who run a restaurant on DineCanvas.
- Diners — customers of a specific restaurant who place an order through that restaurant's DineCanvas-powered website, QR code, or ordering page.
- Website visitors — anyone browsing dinecanvas.in or applying for a demo, before they're a customer at all.
A note on roles under the DPDP Act [CONFIRM WITH COUNSEL]: for owner/staff data, DineCanvas is the Data Fiduciary — we decide why and how that data is processed. For diner data, the relationship is more layered: the restaurant collects the diner's consent and is the merchant the diner is transacting with, while DineCanvas processes that data on the restaurant's behalf to run the ordering, loyalty, and messaging features the restaurant has turned on. We are flagging this distinction explicitly because it affects who is legally the Data Fiduciary versus a processor for diner data, and that classification should be confirmed by counsel before this Policy is finalized — the operational description below is accurate regardless of how that classification lands.
3. Data Fiduciary details
- Entity name: [LEGAL ENTITY NAME]
- Registered address: [REGISTERED ADDRESS]
- CIN / business registration number: [CIN OR EQUIVALENT]
- Contact e-mail: [PRIVACY CONTACT EMAIL, e.g. privacy@dinecanvas.in]
4. Personal data we collect
4.1 If you're a restaurant owner or staff member
When DineCanvas issues you access to the Platform, we collect and store:
- Your name, role, department, employment status, and start/end dates.
- A DineCanvas-issued access code or employee code and a 6-digit PIN, which together are how you sign in. (Note: the e-mail address tied to your login is a system-generated address used only for authentication — it is not an address we send mail to or that identifies you elsewhere.)
- For owners specifically: a recovery e-mail address you give us, used only to send account-recovery links and account notices — never marketing.
- If your restaurant uses the Team/Compensation feature: compensation details your restaurant's owner or manager enters (base pay, rate type, allowances) — this is visible only to your restaurant's own owner/manager roles under our access controls, never to DineCanvas platform staff in the ordinary course, and never shared outside your restaurant.
- Any photos, menu content, brand descriptions, or business documents your restaurant uploads to build its website, menu, or brand profile.
- Records of your own actions on the Platform (orders you process, changes you make) as part of the operational audit trail restaurants rely on for accountability.
4.2 If you're a diner ordering through a DineCanvas-powered restaurant
When you order through a restaurant's DineCanvas ordering page or scan a table QR code, we (on that restaurant's behalf) collect:
- Your phone number, which we verify with a one-time code — this is how the restaurant identifies you as a returning guest and sends order-status updates.
- Your name, if you provide it, and any note you add to your order.
- If the restaurant offers a loyalty/guest-preferences feature and you've visited before: your visit history, loyalty points, preferences, and (if you've shared it) your birthday.
- Marketing consent, separately and explicitly: at checkout you may see a clearly separate checkbox — *"Send me offers & updates from this restaurant. You can opt out anytime — this is separate from order updates."* We only send marketing messages if you check this box, we log that consent (what you agreed to, when, and how), and you can withdraw it at any time; withdrawing it never affects your ability to place or track orders, since order-status messages are never conditioned on marketing consent.
4.3 If you're a website visitor or demo applicant
If you browse dinecanvas.in, we don't track you with analytics or advertising cookies — we don't currently run any (see Section 11). If you apply for a demo, we collect the business name, your name, e-mail, and phone number, your city, anything you write in the message field, and any proof-of-business documents you choose to upload (for example a GST certificate, a shop photo, or a utility bill) so we can verify you're a real restaurant before granting demo access.
5. How and why we use your personal data
We use personal data only for the purposes below, and we don't use it for purposes incompatible with why it was collected:
- To create and secure your account, and to authenticate you (owners, staff).
- To operate the ordering flow — taking orders, sending status updates, and enabling the restaurant to fulfil them (diners).
- To verify demo applicants are real businesses before granting access (website visitors).
- To send transactional communications: order confirmations and status, account and billing notices, password/PIN recovery links, and — for owners — the monthly performance report.
- To send marketing messages, only where you've given specific, opt-in consent for that (diners' restaurant-offer consent; and, separately, any owner communications you've opted into).
- To detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations, including tax, accounting, and law-enforcement requests where legally required.
6. Legal basis / consent
Under the DPDP Act, we process personal data either with your consent or where a "legitimate use" exemption applies (for example, when you voluntarily provide data to us for a specified purpose and haven't indicated you don't consent, such as placing an order). Where we rely on consent — most notably diner marketing messages — that consent is itemized, specific, and freely withdrawable, exactly as described in Section 4.2. [COUNSEL: confirm which legitimate-use grounds we're relying on for each data flow above, and whether a Consent Manager framework applies to us.]
7. Who we share data with
We share personal data only with the service providers who help us run the Platform, each acting under contractual confidentiality and security obligations, and only to the extent needed for their function:
- Supabase — our database, authentication, and file-storage provider. [COUNSEL/OPS: confirm and disclose the hosting region(s) once the production project is provisioned — see Section on cross-border transfer below.]
- Resend — our transactional e-mail provider, used to deliver account notices, recovery links, and (for owners who opt in) reports.
- Meta (WhatsApp Business Platform) — used, only for restaurants that have connected it, to send order-verification codes, order-status updates, and (with your opt-in consent) marketing messages over WhatsApp.
- Razorpay / Paytm — payment processors. [Update once live: currently, live restaurant payments are UPI-direct rather than routed through a gateway; this will change once gateway integration and DineCanvas's own subscription billing go live — this Policy will be updated at that time to describe what payment data each processor receives.]
- Our AI content provider (currently one of Google Gemini, OpenAI, or Groq, depending on configuration) — used only for restaurants generating a website, brand profile, or digitizing a menu from a photo; uploaded images and menu documents are sent to this provider solely to produce that generated content.
We do not sell personal data, and we do not share it with third parties for their own independent marketing purposes.
Cross-border transfer: some of the providers above may process or store data outside India. The DPDP Act permits this except to countries the Central Government restricts by notification; we do not transfer personal data to any such restricted destination. [COUNSEL/OPS: confirm final processor list and hosting regions before publishing, and add specifics here.]
8. Data retention and deletion
We keep personal data only as long as needed for the purposes above, or as required by law. In practice:
- If a restaurant's DineCanvas account is closed, we retain the restaurant's data for a limited window (currently 30 days) during which the owner can export it or reverse the closure, after which it is permanently deleted from our active systems.
- A diner can ask their restaurant (or us, on the restaurant's behalf) to erase their personal data; where full deletion isn't immediately possible (for example, order records needed for tax purposes), we anonymize the data instead so it's no longer linked to you as an identifiable person.
- Marketing consent withdrawal is recorded and acted upon immediately going forward.
9. Data security
We apply reasonable technical and organizational security measures appropriate to the sensitivity of the data — including encryption in transit, role-based access controls so that, for example, only a restaurant's own managers can see that restaurant's staff compensation data, and audit logging of sensitive account actions. No system is completely secure, and we encourage you to also protect your own login credentials.
10. Your rights as a Data Principal
Under the DPDP Act, you have the right to:
- Access a summary of the personal data we hold about you and how it's being processed.
- Correct, complete, or update inaccurate or outdated personal data.
- Erase personal data that is no longer necessary for the purpose it was collected for, or that you've withdrawn consent for.
- Withdraw consent at any time, as easily as you gave it (for example, unchecking a marketing preference).
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
- Grievance redressal — raise a complaint with us first (see Section 13), and if unresolved, escalate to the Data Protection Board of India.
To exercise any of these rights, contact us at [PRIVACY CONTACT EMAIL] or, if you're a diner, ask your restaurant directly — they can route the request to us.
11. Cookies
We currently use only one kind of cookie: the session cookie set when you sign in, which keeps you logged in. We don't use third-party advertising or analytics cookies or trackers on the Platform today. If that changes, we'll update this section and, where required, ask for your consent first.
12. Children's data
The Platform is intended for use by restaurant businesses and their adult staff, and by diners placing food orders. We don't knowingly direct the Platform at children or seek verifiable parental consent, as we don't intentionally collect data that would identify a user as a child. [COUNSEL: confirm whether any additional DPDP children's-data safeguards are needed given diners of unknown age may use the ordering flow.]
13. Grievance Officer
If you have a complaint or question about how your personal data is handled, contact our Grievance Officer:
- Name: [GRIEVANCE OFFICER NAME]
- E-mail: [GRIEVANCE OFFICER EMAIL]
- Address: [GRIEVANCE OFFICER / REGISTERED ADDRESS]
We aim to acknowledge grievances within [NUMBER] days and resolve them within the timeline required by law.
14. Changes to this Policy
We may update this Policy from time to time. We'll post the revised version here with an updated "Last updated" date, and where a change is material, we'll take reasonable steps to notify affected users directly.
15. Governing law and jurisdiction
This Policy is governed by the laws of India. Any disputes are subject to the exclusive jurisdiction of the courts in [CITY], India. [COUNSEL: confirm city/venue.]
16. Contact us
Questions about this Policy: [PRIVACY CONTACT EMAIL]